<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama read only with read only context switching via SAML? in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-read-only-with-read-only-context-switching-via-saml/m-p/1225390#M2826</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34542"&gt;@drewdown&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is documented in the KB&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004LlvCAE&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004LlvCAE&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
    <pubDate>Wed, 02 Apr 2025 04:15:47 GMT</pubDate>
    <dc:creator>ozheng</dc:creator>
    <dc:date>2025-04-02T04:15:47Z</dc:date>
    <item>
      <title>Panorama read only with read only context switching via SAML?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-read-only-with-read-only-context-switching-via-saml/m-p/1223467#M2806</link>
      <description>&lt;P&gt;Can someone please tell me if this is possible?&amp;nbsp; This is on 11.1.6.&amp;nbsp; &amp;nbsp; This worked fine in 9.1 on our previous panorama but not working in 11.1.6 on our newer one.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I need is to be able to allow users to login via SAML and get RO access to panorama and allow them to context switch to the firewalls and get read only there as well.&amp;nbsp; I have SAML auth profile and local admin profile (device-ro-role on each local firewall) to allow device context switching already but unable to make it work.&amp;nbsp; In the past we created the admin profiles and assigned that role to them.&amp;nbsp; But in 11.1.6 I cannot select the admin profiles, they simply don't show up in the drop down menu after selecting the &lt;STRONG&gt;saml auth&lt;/STRONG&gt; profile &amp;gt; admin type &lt;STRONG&gt;custom panorama admin&lt;/STRONG&gt; and then profile.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Part of this is my mistake, I had to change the admin profile to&amp;nbsp;&lt;STRONG&gt;panorama&amp;nbsp;&lt;/STRONG&gt;which allowed me to select it.&amp;nbsp; But when I do that and add the device admin role (which is configured on all the firewalls) and then login using my SAML account I get admin access and when I try to context switch it tells me&amp;nbsp; '&lt;STRONG&gt;Device Admin Role for this role based admin has not been defined.&lt;/STRONG&gt;'&amp;nbsp; &amp;nbsp; So this is broken as its not giving me read only access and its not allowing me to context switch.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PAN admin role:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_0-1741717873497.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66594i40201937CD221473/image-size/medium?v=v2&amp;amp;px=400" role="button" title="drewdown_0-1741717873497.png" alt="drewdown_0-1741717873497.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Local device role (pushed via global template):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_0-1741718022932.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66595i66E8B5D516DE35CE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="drewdown_0-1741718022932.png" alt="drewdown_0-1741718022932.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 18:56:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-read-only-with-read-only-context-switching-via-saml/m-p/1223467#M2806</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2025-03-11T18:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama read only with read only context switching via SAML?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-read-only-with-read-only-context-switching-via-saml/m-p/1225390#M2826</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34542"&gt;@drewdown&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is documented in the KB&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004LlvCAE&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004LlvCAE&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 04:15:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-read-only-with-read-only-context-switching-via-saml/m-p/1225390#M2826</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2025-04-02T04:15:47Z</dc:date>
    </item>
  </channel>
</rss>

